D. Kumar, Somnath Chakrabarti, A. S. Rajan, Jim Huang
{"title":"Scaling Telecom Core Network Functions in Public Cloud Infrastructure","authors":"D. Kumar, Somnath Chakrabarti, A. S. Rajan, Jim Huang","doi":"10.1109/CloudCom49646.2020.00006","DOIUrl":"https://doi.org/10.1109/CloudCom49646.2020.00006","url":null,"abstract":"Telecommunication networks, especially 5G, typify high performance network infrastructure with very high data rates and throughput. Traditionally, high data rates meant line rate in telecom networks. As link capacities increase to 100 Gbit/s, 64byte packet rates will need to reach 150 MPPS. Technologies that attempt to deliver this high packet rate take liberties with proprietary hardware and application-enhanced networking stacks, pushing complexity and cost. Our approach challenges the need to deliver 64byte packet at line rate and instead addresses delivering good enough packet processing capacity with conventional networking stacks natively in the Public Cloud. We explore the deployment of operational telecom core network packet processing on Public Cloud infrastructure and empirically demonstrate this is in fact completely feasible. Using compute and networking available on Public Cloud as is, we realize an end-to-end operational telecom packet core delivering over 2 MPPS, ~20Gbps for 250K users, representing the network load of a Mobile Edge site. This paper re-thinks telecom core network capacity planning, addresses scale-up vs. scale out thresholds, details leveraging of Linux kernel advancements for compute and I/O efficiencies and provides a reference architecture for deployment of telecom core on Public Cloud.","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"131066502","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"On Evolving Software Defined Storage Architecture","authors":"Arun Raghunath, Yuexian Zou, Anjaneya R. Chagam","doi":"10.1109/CloudCom49646.2020.00008","DOIUrl":"https://doi.org/10.1109/CloudCom49646.2020.00008","url":null,"abstract":"","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"116 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"122977564","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"[Title page i]","authors":"","doi":"10.1109/cloudcom49646.2020.00011","DOIUrl":"https://doi.org/10.1109/cloudcom49646.2020.00011","url":null,"abstract":"","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"37 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"123401298","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
M. Ghorbani, F. F. Moghaddam, Mengyuan Zhang, M. Pourzandi, K. Nguyen, M. Cheriet
{"title":"Malchain: Virtual Application Behaviour Profiling by Aggregated Microservice Data Exchange Graph","authors":"M. Ghorbani, F. F. Moghaddam, Mengyuan Zhang, M. Pourzandi, K. Nguyen, M. Cheriet","doi":"10.1109/CloudCom49646.2020.00004","DOIUrl":"https://doi.org/10.1109/CloudCom49646.2020.00004","url":null,"abstract":"In the recent literature, Machine Learning (ML) techniques are increasingly used to detect the abnormal behaviour for different applications. Recently, these applications have moved to the cloud and virtualized environments due to the unique benefits such as deployment agility, scalability, flexibility and resiliency. However, those benefits pose a new challenge for classical ML approaches to accurately identify abnormal behaviours due to their highly dynamic and heterogeneous nature. In this paper, we propose a new approach Malchain for profiling virtual applications based on using a new concept: microservice role. The roles are used to provide a consistent view of the virtual application addressing the mentioned new challenges. The microservice data exchange graph built using this consistent view is then used to extract features providing the appropriate measures to profile the aggregated behaviour of the microservices comprising a virtual application. We show the efficiency and feasibility of our approach by implementing several different real-world attacks, and measuring high detection rates (86%-99%) for those attacks.","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"24 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"114873174","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"Stateful Container Migration in Geo-Distributed Environments","authors":"P. S. Junior, D. Miorandi, G. Pierre","doi":"10.1109/CloudCom49646.2020.00005","DOIUrl":"https://doi.org/10.1109/CloudCom49646.2020.00005","url":null,"abstract":"Container migration is an essential functionality in large-scale geo-distributed platforms such as fog computing infrastructures. Contrary to migration within a single data center, long-distance migration requires that the container's disk state should be migrated together with the container itself. However, this state may be arbitrarily large, so its transfer may create long periods of unavailability for the container. We propose to exploit the layered structure provided by the OverlayFS file system to transparently snapshot the volumes' contents and transfer them prior to the actual container migration. We implemented this mechanism within Kubernetes. Our evaluations based on a real fog computing test-bed show that our techniques reduce the container's downtime during migration by a factor 4 compared to a baseline with no volume checkpoint.","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"11 suppl_1 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"126049767","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"[Copyright notice]","authors":"","doi":"10.1109/cloudcom49646.2020.00013","DOIUrl":"https://doi.org/10.1109/cloudcom49646.2020.00013","url":null,"abstract":"","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"32 6 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"123520183","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Alaa Oqaily, Sudershan L T, Yosr Jarraya, Suryadipta Majumdar, Mengyuan Zhang, M. Pourzandi, Lingyu Wang, M. Debbabi
{"title":"NFVGuard: Verifying the Security of Multilevel Network Functions Virtualization (NFV) Stack","authors":"Alaa Oqaily, Sudershan L T, Yosr Jarraya, Suryadipta Majumdar, Mengyuan Zhang, M. Pourzandi, Lingyu Wang, M. Debbabi","doi":"10.1109/CloudCom49646.2020.00003","DOIUrl":"https://doi.org/10.1109/CloudCom49646.2020.00003","url":null,"abstract":"Network Functions Virtualization (NFV) enables agile and cost-effective deployment of multi-tenant network services on top of a cloud infrastructure. However, the multi-tenant and multilevel nature of NFV may lead to novel security challenges, such as stealthy attacks exploiting potential inconsistencies between different levels of the NFV stacks. Consequently, the security compliance of a multilevel NFV stack cannot be sufficiently established using existing solutions, which typically focus on one level. Moreover, the naive approach of separately verifying every level could be expensive or even infeasible. In this paper, we propose, NFVGuard, the first multilevel approach to the formal security verification of NFV stacks. Our key idea is to conduct the security verification at only one level, and then assure that verification result for other levels by verifying the consistency between adjacent levels. We integrate NFVGuard with OpenStack/Tacker, a popular platform for the NFV deployment, and experimentally evaluate its effectiveness.","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"2000 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"116680476","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Chetankumar Mistry, Bogdan Stelea, Vijay Kumar, Thomas Pasquier
{"title":"Demonstrating the Practicality of Unikernels to Build a Serverless Platform at the Edge","authors":"Chetankumar Mistry, Bogdan Stelea, Vijay Kumar, Thomas Pasquier","doi":"10.1109/CloudCom49646.2020.00001","DOIUrl":"https://doi.org/10.1109/CloudCom49646.2020.00001","url":null,"abstract":"The rise of IoT has led to large volumes of personal data being produced at the network's edge. Most IoT applications process data in the cloud raising concerns over privacy and security. As many IoT applications are event-based and are implemented on cloud-based, serverless platforms, we've seen a number of proposals to deploy serverless solutions at the edge to address concerns over data transfer. However, conventional serverless platforms use container technology to run user-defined functions. Containers introduce their own issues regarding security - due to a large trusted computing base -, and performance issues including long initialisation times. Additionally, OpenWhisk a popular and widely used container-based serverless platform available for edge devices perform relatively poorly as we demonstrate in our evaluation. In this paper, we propose to investigate unikernel as a solution to build serverless platform at the edge, addressing in particular performance and security concerns. We present UniFaaS, a prototype edge-serverless platform which leverages unikernels - tiny library single-address-space operating systems that only contain the parts of the OS needed to run a given application - to execute functions. The result is a serverless platform with extremely low memory and CPU footprints, and excellent performance. UniFaaS has been designed to be deployed on low-powered single-board computer devices, such as Raspberry Pi or Arduino, without compromising on performance.","PeriodicalId":401135,"journal":{"name":"2020 IEEE International Conference on Cloud Computing Technology and Science (CloudCom)","volume":"137 1","pages":"0"},"PeriodicalIF":0.0,"publicationDate":"2020-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"115903922","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":0,"RegionCategory":"","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}